Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation advertises capabilities to read files, write files, inspect project directories, and fetch GitHub-based templates, but no explicit permissions are declared. That mismatch can cause the agent to perform filesystem and network actions without clear user-visible authorization boundaries, increasing the risk of unintended file modification or external data access. In this context the behavior is expected for the feature set, but the lack of declared permissions is still a real security weakness rather than an exploit by itself.
